Secrets management
Secrets include credentials, tokens, and encryption keys.
What it is
Secrets include credentials, tokens, and encryption keys.
When to use it
Keep them out of source, responses, and diagnostics.
Syntax
// config/services.php
"bank" => ["key" => env("BANK_API_KEY")],Example
// .env is excluded from Git.
$key = config("services.bank.key");
// Rotate leaked keys and revoke old access.
// Grant each credential the minimum scope required.Common mistakes
Removing a secret from the latest commit does not remove history; never publish .env or APP_KEY.